DiscoverCyber Security District
Cyber Security District
Claim Ownership

Cyber Security District

Author: Cyber Security District

Subscribed: 41Played: 98
Share

Description

The interview podcast for cyber security professionals and for those who aspire to become one. We interview industry experts to get to know the latest trends, real life war stories and everything you need to know about this exciting industry.
52 Episodes
Reverse
The Rise of Identity-Based Attacks with Olivier Eyries | Saporo What if you could see your entire attack surface the way a hacker does and fix it before they strike? In this episode, hosts Laurens Jagt sit down with Olivier Eyries, co-founder and CEO of Saporo, one of Switzerland's fastest-growing cybersecurity startups. Saporo helps organisations stop hackers by identifying and eliminating identity risks before attackers can exploit them. Olivier is a serial entrepreneur with two previous ventures under his belt, including one sold to Proofpoint in 2021. He and his co-founders built what he calls a "Google Maps for cybersecurity": a graph-based platform that maps every attack path, every permission, and every identity risk across an organisation's environment. In this conversation, he breaks down why identity-based attacks have exploded, what AI agents mean for the attack surface, and why fixing one permission can block millions of potential attack paths. In this episode: Olivier's journey: from dropping out at 21 to two exits and founding Saporo Why identity-based attacks have exploded and AI is accelerating the trend The graph-based approach: visualising attack paths the way hackers do Non-human identities: why AI agents are the next major attack surface How cutting one permission can block millions of attack paths Saporo's 98% renewal rate and €7M funding round The European funding gap and why Olivier is expanding into the US Timestamps: 00:00 Introduction 01:03 Olivier's entrepreneurial journey: from dropout to two exits 04:12 The founding of Saporo: right tech, right team, right time 05:33 The Google Maps for cybersecurity concept 09:09 €7M raised and building through three stages of startup growth 11:02 Graph-based approach to identity risk and attack paths 16:14 How Saporo prioritises which attack paths to cut first 22:32 AI's impact on cybersecurity and Saporo's product roadmap 23:43 Non-human identities: the next major attack surface 29:19 What CISOs need to do right now about AI agents 34:17 Saporo's next milestones: US expansion and customer success 37:26 The European funding gap and why it matters for founders 43:49 Signal message to CISOs: give European founders a shot 44:42 Final thoughts: stay humble, ask the question, build now Connect with the guests: Olivier Eyries: https://www.linkedin.com/in/olivier-eyries/ Website: https://www.saporo.io/   Follow Cyber Security District: Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Jeroen Prinse on LinkedIn: https://www.linkedin.com/in/jprinse/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What if your infrastructure was built secure from minute one and stayed that way? In this special one year anniversary episode of Cyber Security District, host Jeroen Prinse sits back down with Mahdi Abdulrazak (CEO) and Kim van Lavieren (CTO) of Dawnguard, a security automation platform that turns approved security architecture directly into deployable cloud infrastructure as code. One year in, having just closed a pre-seed round and raised €6.3 million in total funding and opening a new office in New York, Dawnguard is making a bold bet: that the only real answer to modern cyber threats isn't better detection or faster patching, it's building systems that are resilient by design from the very start. Mahdi and Kim have both led security teams inside large organisations and lived through the same recurring nightmare: architecture locked in too early, security reviews arriving too late and a list of 50 findings that nobody has time to fix before the product ships. Dawnguard was built to break that cycle, with a collaborative canvas that lets teams design, validate and deploy secure infrastructure in minutes, with continuous drift detection to make sure it stays that way. One year on, we look back at how far that idea has come and what's next as the company expands. Key Takeaways:     You cannot patch your way out of agentic AI attacks, the only answer is building more resilient systems from the start     The hardest translation in security is from policy to architecture, ambiguity and contradictions there cascade into every layer below     Context is the missing ingredient in most security tooling: secure or insecure is a binary lens that doesn’t reflect reality     Drift detection only works when you know what was approved in the first place, that’s the advantage of integrating into the design lifecycle     Security decisions still belong to the business and engineers, Dawnguard removes the friction, not the ownership     The shift from protection to resilience is already happening: it’s not if you get breached, it’s how contained the blast radius is     European founders can compete, but capital conviction from investors matters as much as capital volume Timestamps: 00:00 – Introduction 00:15 – Meet Dawnguard 00:48 – One year in: what proved Dawnguard was solving a real problem 01:30 – How customers are using the platform today: discover, design, deploy, monitor 03:20 – The shift-left moment: when architecture gets locked in and it’s already too late 05:15 – why organisations overestimate their resiliency requirements 06:15 – What Snyk, OPA and Sentinel leave unresolved  08:30 – Guardrails vs. findings: preventing vulnerabilities instead of just reporting them 09:30 – Policy to architecture to code to production: where is the hardest translation? 11:00 – The Mythos era: agentic AI and why patching is a losing strategy 12:50 – The shift from protection to resilience 15:00 – Blast radius reduction and the holistic trade-off view Dawnguard provides 16:45 – Drift detection: how Dawnguard tells a legitimate change from a malicious one 18:20 – Prompting redesigns for cost, sustainability, and resilience 20:00 – Bringing guardrails into the developer IDE in real time 22:25 – Who owns the security decision? 25:45 – European digital sovereignty: what it concretely means for Dawnguard 27:55 – Raising €6.3 million from European funds in year one 29:10 – What excites Mahdi and Kim most about the road ahead 30:40 – Final message: what CISOs should be doing differently a year from now Connect with the guests: Mahdi Abdulrazak: https://www.linkedin.com/in/mahdiabdulrazak/ Kim van Lavieren: https://www.linkedin.com/in/kim-v-0645931b4/ Website: https://www.dawnguard.io/ Follow Cyber Security District: Jeroen Prinse on LinkedIn: https://www.linkedin.com/in/jprinse/ Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What does it take to build a cybersecurity company not once, but twice from the ground up? In this episode of Cyber Security District, we sit down with Francisco Nina Rente, one of Portugal's most accomplished cybersecurity entrepreneurs. Francisco started his journey as a teenager tinkering with computers and quickly found his way into ethical hacking and open-source security communities. That curiosity became a career, which then led to a company. His first venture grew from a university incubator into a 250-person operation delivering services across 22 countries, before being acquired by a global security group. After years scaling that business from the inside and taking on roles as country manager, CTO and board member, Francisco stepped away to build again. This time, the mission is clearer: help organisations stop just detecting threats and start truly recovering from them. Art Resilia was born out of a conviction that the market was shifting from cybersecurity to cyber resilience, and Francisco positioned the company right at the centre of that shift. Key Takeaways: Cyber resilience is about recovery, not just defence Focus beats opportunity-chasing, especially in the early days of a startup The Commonwealth of a team always comes before individual interest Trust-based security communication outlasts fear-based selling every time Knowledge remains the core differentiator, even in the age of AI Timestamps: 00:00 – Introduction 01:20 – From a family computer to a hacker mindset 04:00 – First paid gig: penetration testing for hardware 05:30 – Building Portugal's first incident response team at university 09:00 – Selling trust, not fear: early media and awareness work 11:00 – Scaling to 22 countries and finding the right investors 15:30 – The acquisition: joining a global security group 20:00 – Growing into CTO and leaving on his own terms 22:00 – The idea behind Art Resilia and reading the market shift 24:30 – The name: "The Art of Resilience" 25:00 – Where Art Resilia stands today: 50 people, 4 countries 27:00 – Why the Netherlands and Benelux? 28:00 – Lessons from 20 years of building: focus, people, pragmatism 33:00 – Culture, remote work, and hiring for values first 40:00 – What's next for Art Resilia in 3–5 years 43:00 – AI in cybersecurity: tool or transformation? 45:30 – Advice for young professionals entering the field 52:00 – Final message to CISOs: protect both business confidentiality and individual privacy Connect with the guest: Francisco Nina Rente: https://www.linkedin.com/in/frente/ Website: https://www.artresilia.com   Follow Cyber Security District: Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What if you could clone your best cybersecurity consultant and put them to work on five engagements at once? In this episode of Cyber Security District, we sit down with Leslie Clement and Erie Berhitu, co-founders of Clember AI, an EU-first, AI-native platform built to automate the repetitive, time-consuming work that holds cybersecurity consultants back. Both Leslie and Erie spent years grinding through the same manual loops at major consultancy firms document analysis, gap assessments, risk reports, roadmaps before deciding enough was enough. Rather than build another consulting firm or hire more headcount, they built a platform. Clember AI now enables security consultants to run five or more client engagements simultaneously, with consistent, high-quality output every time. And they did it entirely bootstrapped, no VC, no investor pressure, just product-market fit and a clear-eyed vision of where cybersecurity consulting is heading. In this episode, we explore: How a company getting hacked on day one of the job launched Leslie’s career in cybersecurity The year-long frustration that led Erie and Leslie to build Clember AI instead of another consulting firm Why they chose to stay bootstrapped despite investor interest  and why they don’t regret it How Clember AI automates the full consulting lifecycle: document ingestion, gap analysis, risk translation, and reporting Why consistency across junior and senior consultants is a bigger deal than most firms admit The shift from hourly billing to monthly retainers and how Clember keeps consulting firms “interesting” to clients year three and beyond Their vision: becoming the Datasnipper of cybersecurity consulting Why embracing AI is non-negotiable for CISOs  and why helping early-stage startups matters for the whole industry Timestamps: 00:00 – Introduction 00:15 – Meet Leslie Clement and Erie Berhitu 01:40 – How Erie got into cybersecurity (and why it wasn’t exactly planned) 02:45 – Leslie’s rough first day: getting hacked with no tech team 04:00 – The shared frustration that sparked Clember AI 06:10 – Why they chose to build a tech firm instead of a consulting firm 08:30 – The first product concept: automating the questionnaire 11:20 – Who Clember AI is actually for: cybersecurity consultancy firms 14:00 – Billable hours vs. scale: how Clember changes the math 17:30 – The shift from hourly billing to monthly retainers and staying interesting in year three 22:00 – Will AI kill traditional consultancy? Leslie and Erie’s take 25:10 – How Clember works: document ingestion, gap analysis, risk translation, roadmaps 29:00 – Consistency across consultant seniority levels 31:30 – Hiring technical talent as non-technical founders 34:00 – Staying bootstrapped despite VC interest  and why pivoting was easier without investor pressure 38:30 – What made Clember appealing at an early stage 41:00 – The hiccups: work-life balance, family, and knowing when to step away 44:30 – Gut feeling vs. rational decision-making as founders 48:00 – The vision: Clember as the Datasnipper for cybersecurity consulting 51:30 – What’s next: new markets, sales hires, and scaling customer success 54:00 – Data privacy and security by design inside Clember 57:00 – Final message to CISOs: embrace innovation, and back the startups Connect with the guests: Leslie Clement: https://www.linkedin.com/in/leslie-clement/ Erie Berhitu: https://www.linkedin.com/in/eberhitu/ Website: https://www.clember.ai/   Follow Cyber Security District: Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict
In this episode of Cyber Security District, we speak with Tom Leijte, founder of Passguard, one of the most exciting emerging cybersecurity companies in the Netherlands. Passguard helps organizations detect when infected devices, stolen credentials, and active sessions show up on criminal marketplaces, giving security teams early visibility before exposure turns into a breach. Tom shares how his journey started outside of “traditional” cybersecurity, working in private investigations where dark web intelligence was already part of high-stakes screening work. Together with his technical co-founder, he built the capabilities to infiltrate closed criminal forums and surface the kind of forensic-level logs most companies never see until it’s too late. In this episode, we cover: Using dark web intelligence for sensitive employee screening Why “classic” dark web monitoring often gets deprioritized by security teams The infostealer shift: stolen session tokens, not just leaked passwords How session theft can bypass MFA and why that changes the game How criminal marketplaces work (and how trust is built among criminals) How Passguard infiltrates closed forums using reputation, escrow, and long-term access Building a European-first solution and partnering with MSSPs / security platforms Scaling after investment: team growth, ICP clarity, and market expansion Timestamps: 00:00 – Intro 00:15 – Meet Tom Leijte and Passguard’s mission 00:37 – Early visibility: exposure before it becomes a breach 01:22 – Tom’s background in private investigations 02:13 – Screening sensitive roles using open-source + dark web sources 03:47 – Why dark web intelligence matters for organizations 04:39 – How Passguard started (and the co-founder story) 05:53 – What surprised Tom most about the dark web 06:20 – Data breaches vs data brokers: what ends up for sale 07:20 – Discovering infostealers and why they’re different 08:17 – Session tokens, MFA bypass, and the “unmanaged endpoint” problem 10:01 – What infostealers capture (sessions, access, and more) 11:10 – Why SaaS + remote work + BYOD changed attacker economics 12:27 – Supplier and branch-office risk: the blind spot organizations miss 14:31 – Why classic “dark web monitoring” wasn’t landing in the market 15:38 – The Mom Test and learning to run real customer conversations 18:08 – Reframing the problem: focusing on infostealer exposure 20:38 – How the dark web works (no “bookmark”, reputation, escrow) 23:11 – Passguard’s approach: bots, reputation, and long-term infiltration 25:55 – Real-world example: infostealers and large-scale government breaches 27:37 – What stolen access is worth and how it gets packaged for sale 29:19 – Screenshots, persistence, and “always up-to-date” stolen sessions 30:05 – Educating customers and turning awareness into action 31:03 – What Passguard delivers: evidence, context, and early alerts 33:08 – The Snowflake case: old credentials, massive impact 36:06 – Scaling after investment: pressure, growth, and coping 37:18 – Why Tom chose experienced cyber investors and operators 39:43 – Passguard as intelligence inside MSP/MSSP security workflows 41:45 – Team expansion and what roles matter most next 43:27 – ICP clarity and European market expansion 45:27 – Signal message to CISOs: give startups a chance early 46:50 – Outro Connect with the guests: Tom Leijte: https://www.linkedin.com/in/tom-leijte-01596536/ Website: https://www.passguard.com/ Follow Cybersecurity District: Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict
loading
Comments